ANNEXURE A: EXPLANATION OF OBLIGATIONS UNDER THE
ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING REGIME 1. Enrol/register with AUSTRAC
Any business that provides a service regulated under the AML/CTF Act must be enrolled on AUSTRAC’s Reporting Entities Roll.
Businesses which intend to provide remittance services (remitters) must also apply to be registered with AUSTRAC.
More than 14,000 regulated businesses across the financial, remittance, gambling and bullion sectors are currently enrolled with, and regulated by, AUSTRAC for their compliance with their AML/CTF Act obligations.
2. Conduct customer due diligence
A regulated business must conduct CDD measures that allow the business to be reasonably satisfied that:
-
an individual customer is who they claim to be, and
-
for a non-individual customer, the customer exists and their beneficial ownership details are known.34
By knowing its customers a regulated business should be better able to identify and mitigate ML/TF risks in the conduct of their financial transactions, particularly where the activity or transactions are unusual or uncharacteristic.
The CDD measures include:
-
collecting and verifying customer identification information - for example, identity documents, data or other information which can be verified using a reliable and independent source
-
identifying and verifying the beneficial owner(s) of a customer
-
identifying whether a customer is a politically exposed person (PEP) (or an associate of a PEP) and taking steps to establish the source of funds used during the business relationship or transaction35
-
ongoing customer due diligence and transaction monitoring, and
-
obtaining information on the purpose and intended nature of the business relationship.
The CDD procedures developed by a regulated business must be included in a business’s AML/CTF program (see below).
3. Implement ongoing customer due diligence procedures
Regulated businesses must have in place appropriate systems and controls to determine whether additional customer information (including beneficial owner information) should be collected and/or verified on an ongoing basis to ensure that it holds up-to-date information about its customers. This process is known as 'ongoing customer due diligence' (OCDD). The decision to apply the OCDD process to a particular customer depends on the customer's level of assessed ML/TF risk.
Ongoing customer due diligence also includes:
-
implementing a transaction monitoring program, and
-
developing an 'enhanced customer due diligence' program (ECDD).
A transaction monitoring program is a program for monitoring transactions using a risk-based approach and allows a regulated business to:
-
identify transactions that are considered to be suspicious, and
-
identify complex, unusually large transactions and unusual patterns of transactions which have no apparent economic or visible lawful purpose.
ECDD is the process of undertaking additional CDD in certain circumstances deemed to be high risk. For example, ECDD may be appropriate where the customer is located in a country where there are weak AML/CTF controls. The ECDD program details the procedures the reporting entity must undertake in these high risk circumstances.
The OCDD procedures developed by a regulated business must be included in the business’s AML/CTF program (see below).
4. Implement and maintain an AML/CTF program
Regulated businesses must develop and maintain a written AML/CTF program that sets out the operational framework for meeting compliance obligations under the AML/CTF Act.
The AML/CTF program must have two parts and should specify how the business identifies, mitigates and manages the risk of its products or services being misused to facilitate ML/TF.
Part A covers identifying, managing and reducing the ML/TF risk faced by a regulated business and includes:
-
an ML/TF risk assessment of the business conducted by the entity
-
approval and ongoing oversight by boards (where appropriate) and senior management
-
appointment of an AML/CTF compliance officer
-
regular independent review of Part A
-
an employee due diligence program
-
an AML/CTF risk awareness training program for employees
-
policies and procedures for the reporting entity to respond to and apply AUSTRAC feedback
-
systems and controls to ensure the entity complies with its AML/CTF reporting obligations, and
-
ongoing customer due diligence (OCDD) procedures (see above).
Part B covers a regulated business’ CDD procedures and includes:
-
establishing a framework for identifying customers and beneficial owners of customers so the reporting entity can be reasonably satisfied a customer is who they claim to be, and
-
collecting and verifying customer and beneficial owner information.
Regulated businesses have a number of ongoing reporting obligations. These obligations relate to:
-
threshold transaction reports (TTRs)
-
international funds transfer instructions (IFTIs) reports, and
-
suspicious matter reports (SMRs) with AUSTRAC.
Where a business provides or commences to provide a regulated service to a customer that involves the payment or transfer of physical currency or e-currency of AUD10,000 or more (or foreign currency equivalent), the business must submit a TTR to AUSTRAC. The TTR must be submitted to AUSTRAC within 10 business days of the transaction taking place.
If a business sends or receives a funds transfer instruction to or from a foreign country, the business must complete an IFTI report. The IFTI report must be submitted to AUSTRAC within 10 business days of sending or receiving the international funds transfer instruction.
If at any time while dealing with a customer the regulated business forms a suspicion on a matter that the regulated business suspects may relate to any serious offence, tax evasion or proceeds of crime, the business must provide a SMR to AUSTRAC. Offences include money laundering, terrorism financing, operating under a false identity or any other offence under Commonwealth, State or Territory law.
Regulated businesses must submit an SMR to AUSTRAC within three business days of forming the suspicion. If the suspicion relates to the financing of terrorism, the SMR must be submitted within 24 hours of forming the suspicion.
Regulated businesses have a range of record-keeping obligations under the AML/CTF Act. These obligations depend on the type of regulated service it provides but generally include records about:
-
transactions
-
electronic funds transfers
-
customer identification procedures
-
AML/CTF programs, and
-
due diligence assessments of correspondent banking relationships.
Do'stlaringiz bilan baham: |